• Amy Griffis's avatar
    [PATCH] add rule filterkey · 5adc8a6a
    Amy Griffis authored
    Add support for a rule key, which can be used to tie audit records to audit
    rules.  This is useful when a watched file is accessed through a link or
    symlink, as well as for general audit log analysis.
    
    Because this patch uses a string key instead of an integer key, there is a bit
    of extra overhead to do the kstrdup() when a rule fires.  However, we're also
    allocating memory for the audit record buffer, so it's probably not that
    significant.  I went ahead with a string key because it seems more
    user-friendly.
    
    Note that the user must ensure that filterkeys are unique.  The kernel only
    checks for duplicate rules.
    Signed-off-by: default avatarAmy Griffis <amy.griffis@hpd.com>
    5adc8a6a
audit.h 4.59 KB